In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2014/06/05/19 | mailing list third party advisory patch |
https://github.com/openshift/openshift-extras/blob/enterprise-2.0/README.md#security-notice | third party advisory |